Port Details - Port 3127

Oct 22 75 Oct 24 87 Oct 25 64 Oct 26 75 Oct 27 79 Oct 28 76 Oct 29 90 Oct 30 80 Oct 31 70 Nov 01 68 Nov 02 77 Nov 03 77 Nov 04 78 Nov 05 65 Nov 06 72 Nov 07 63 Nov 08 58 Nov 09 73 Nov 10 95 Nov 11 65 Nov 12 69 Nov 13 93 Nov 14 50 Nov 15 59 Nov 16 72 Nov 17 58 Nov 18 69 Nov 19 61 Nov 20 53 Oct 22 1,130 Oct 24 597 Oct 25 437 Oct 26 400 Oct 27 982 Oct 28 425 Oct 29 742 Oct 30 402 Oct 31 1,740 Nov 01 1,544 Nov 02 2,047 Nov 03 993 Nov 04 236 Nov 05 109 Nov 06 375 Nov 07 128 Nov 08 931 Nov 09 1,769 Nov 10 2,702 Nov 11 563 Nov 12 629 Nov 13 167 Nov 14 90 Nov 15 379 Nov 16 742 Nov 17 1,008 Nov 18 223 Nov 19 1,706 Nov 20 770
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpmydoomW32/MyDoom, W32.Novarg.A backdoor
tcpctx-bridge
udpctx-bridge
[get complete service list]

User Comment

Submitted ByDate
Comment
2009-10-04 18:45:22
The overwhelming majority of hits I've seen are Doomjuice.A &;; B. Nachi and Vesser have been very rare. I've also been sent "Phatbot3" which is probably a modified version of Argobot.
Karma2009-10-04 18:45:22
Although MyDoom may listen on 3127, this activity is probably that of DoomJuice or Nachi.B/C variants "looking" for MyDoom backdoors.
K-OTik.COM (TechNet)2009-10-04 18:45:22
As you know MyDoom.A machines are exploited by MyDoom.C and Vesser - There is a faster and more dangerous worm exploiting these machines : his name is "kiddies" !! so here is one of the codes used by kiddies to exploit Mydoom.A machines (many other codes in the wild) http://www.securityfocus.com/archive/1/353325 http://www.k-otik.com
Brian Porter2004-02-10 19:50:07
MyDoom.C / Doomjuice http://www.lurhq.com/mydoom-c.html http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.doomjuice.html http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOOMJUICE.A http://us.mcafee.com/virusInfo/default.asp?id=description&;virus_k=101002 http://www.sophos.com/virusinfo/analyses/w32doomjuicea.html http://www.f-secure.com/v-descs/doomjuice.shtml http://www.viruslist.com/eng/alert.html?id=930701
2004-02-06 22:18:53
The Win32.Mydoom computer-virus opens and listens to the TCP port 3127, (if this port is already in use, the worm tries the next one free from the range 3128- 3199). The backdoor appears to have two main functions: execution of remotely-supplied code, and port forwarding. Reference: http://www3.ca.com/virusinfo/virus.aspx?ID=38102
sfuechsli2004-01-27 18:14:12
WORM_MIMAIL.R (Aliases: W32/Mydoom@MM, Mydoom, Win32.Mydoom.A, W32.Novarg.A@mm)
Add a comment

CVE Links

CVE #Description